The Hacker News 🔐 Cybersecurity 👁 0 📖 3 min read

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchang

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

Swati KhandelwalOct 08, 2026Cybercrime / Cyber Espionage

The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM.

The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice from the department's Rewards for Justice program.

Zhang remains at large, U.S. authorities say, meaning he has not been arrested. The charges against him have not been tested in court.

Rewards for Justice is the State Department's national security rewards program. It says it has paid more than $250 million to over 125 people since 1984.

Zhang is wanted for his alleged role in "malicious cyber activities against U.S. critical infrastructure," NTD quoted the notice as saying.

The amount and that wording match an offer the program was already making in January 2025. That offer was for information on anyone who hacks U.S. critical infrastructure at the direction of a foreign government.

Zhang and a second man, Xu Zewei, are charged together in federal court in Houston. The indictment, the document that sets out the charges, has nine counts.

It dates from November 2023 and was made public in July 2025. Since then, the Justice Department has asked the public for information about Zhang's whereabouts.

The alleged hacking took place between February 2020 and June 2021.

Xu was arrested in Milan in July 2025 at the request of the United States, and Italy extradited him to the United States in April 2026.

Xu "is one of many contractors the Chinese government uses to obscure its hand in cyber operations, and others who do the same face the same risk," Brett Leatherman, assistant director of the FBI's Cyber Division, said at the time.

What Zhang Is Accused Of

U.S. authorities describe Zhang as a director at Shanghai Firetech Information Science and Technology, a Shanghai company.

According to the indictment, he worked on tasks assigned by the Shanghai State Security Bureau, supervised hacking by other Firetech staff, and coordinated the hacking with Xu. The bureau is a branch of China's Ministry of State Security (MSS), an intelligence service.

Xu allegedly worked for a second Shanghai company, Shanghai Powerock Network. The Justice Department calls Powerock one of many "enabling" companies that hacked for the Chinese government, and says China uses private companies and contractors to hide its role.

The indictment alleges two sets of intrusions. The first, in early 2020, targeted U.S. universities and scientists working on COVID-19 vaccines, treatment, and testing. The second, from late 2020, exploited flaws in Microsoft Exchange Server in the campaign later called HAFNIUM.

On or about January 30, 2021, Xu allegedly told Zhang he had compromised a Texas university's network.

The alleged victims include two Texas universities and an international law firm with an office in Washington, D.C.

The HAFNIUM Campaign

Microsoft disclosed the Exchange attacks on March 2, 2021, and released fixes for four zero-day flaws, including the one known as ProxyLogon.

It blamed HAFNIUM, which it described as "a group assessed to be state-sponsored and operating out of China." Microsoft now tracks the group as Silk Typhoon.

Within days, Microsoft saw other hacking groups using the same flaws.

The FBI says the HAFNIUM campaign as a whole compromised more than 12,700 U.S. organizations.

In July 2021, the United States and partner governments said hackers linked to the MSS carried out the campaign. Microsoft's 2021 report named a group and a country. The names Xu Zewei and Zhang Yu come from the U.S. indictment.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
⭐ Featured Resources
📰 Read the original article on The Hacker News

Originally published by The Hacker News. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.